Description
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Published: 2026-08-19
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM OpenBMC firmware revisions FW1060.00 through FW1060.80 contain a flaw in the firmware update process that allows an attacker who has authenticated administrator‑level access to a Baseboard Management Controller to execute arbitrary code. The flaw is classified as a CWE‑22 type vulnerability involving improper handling of control data during the update sequence and can compromise confidentiality, integrity and availability.

Affected Systems

The affected products are IBM OpenBMC firmware images FW1060.00 to FW1060.80. The flaw applies to IBM Power System models: Power System S1022 (9105‑22A), S1024 (9105‑42A), S1022s (9105‑22B), S1014 (9105‑41B), L1022 (9786‑22H), L1024 (9786‑42H), E1050 (9043‑MRX), and S1012 (9028‑21B).

Risk and Exploitability

The CVSS base score of 6.8 indicates medium severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authenticated administrator access to the BMC and occurs during the firmware update process, so the threat is limited to environments where the BMC interface is reachable by an authenticated user.

Generated by OpenCVE AI on August 20, 2026 at 11:23 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability. Power 10 1) IBM Power System S1022 (9105-22A) 2) IBM Power System S1024 (9105-42A) 3) IBM Power System S1022s (9105-22B) 4) IBM Power System S1014 (9105-41B) 5) IBM Power System L1022 (9786-22H) 6) IBM Power System L1024 (9786-42H) 7) IBM Power System E1050 (9043-MRX) 8) IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

Protect access to the BMC's administrative interface.  Install firmware images only from trusted sources.  Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.


OpenCVE Recommended Actions

  • Install IBM firmware FW1060.81(1060_191) or newer on all affected Power Systems listed above
  • Restrict access to the BMC administrative interface by limiting it to trusted administrators and using strong authentication
  • Only install firmware images from trusted sources and validate each image’s integrity following the release notes guidelines

Generated by OpenCVE AI on August 20, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1050_\(9043-mrx\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022_\(9786-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024_\(9786-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1012_\(9028-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014_\(9105-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022_\(9105-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s_\(9105-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024_\(9105-42a\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1050_\(9043-mrx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1022_\(9786-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1024_\(9786-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1012_\(9028-21b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1014_\(9105-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022s_\(9105-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1024_\(9105-42a\)_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Title IBM OpenBMC Code Execution
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-22
CPEs cpe:2.3:o:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:fw1060.80:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Openbmc Power System E1050 \(9043-mrx\) Power System E1050 \(9043-mrx\) Firmware Power System L1022 \(9786-22h\) Power System L1022 \(9786-22h\) Firmware Power System L1024 \(9786-42h\) Power System L1024 \(9786-42h\) Firmware Power System S1012 \(9028-21b\) Power System S1012 \(9028-21b\) Firmware Power System S1014 \(9105-41b\) Power System S1014 \(9105-41b\) Firmware Power System S1022 \(9105-22a\) Power System S1022 \(9105-22a\) Firmware Power System S1022s \(9105-22b\) Power System S1022s \(9105-22b\) Firmware Power System S1024 \(9105-42a\) Power System S1024 \(9105-42a\) Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-21T16:13:25.891Z

Reserved: 2026-08-04T15:35:55.877Z

Link: CVE-2026-18849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T21:16:54.663

Modified: 2026-09-02T18:58:30.013

Link: CVE-2026-18849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')